File Notification Attacks: Side-Channel Leakage from the File-Notification System
File-change notifications can leak user activity even when an observer cannot read the files themselves. Researchers from Graz University of Technology demonstrate attacks across Linux, Android, Windows, and macOS, including Linux keystroke timing and Android cross-app file-activity inference. Their paper has been accepted to ACM CCS 2026; the reported accuracy figures come from the researchers’ experiments, not evidence of broad exploitation.
Linux’s CVE-2025-68788 received a partial fix for events on special files in /dev; the researchers say other platform-specific exposure remains. In the Lobsters discussion, one commenter asked whether stat/atime already exposed similar information; the author replied that relatime and special device files make that an inadequate explanation or mitigation. Another commenter questioned why character devices track mtime and ctime separately.